MS.Word.HTML.CSS.Double.Free
Description
This indicates an attempt to exploit a double-free vulnerability in Microsoft Word.
The vulnerabilities are caused by an error that occurs when the vulnerable software handles a malicious DOC file. A remote attacker may exploit this to execute arbitrary code via a crafted DOC file.
Affected Products
Microsoft Office 2000 Service Pack 3
Microsoft Office XP Service Pack 3
Microsoft Office 2003 Service Pack 2
Microsoft Office 2003 Service Pack 3
2007 Microsoft Office System
Microsoft Outlook 2007
2007 Microsoft Office System Service Pack 1
Microsoft Outlook 2007 Service Pack 1
Microsoft Word Viewer 2003
Microsoft Word Viewer 2003 Service Pack 3
Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats
Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats Service Pack 1
Microsoft Office 2004 for Mac
Microsoft Office 2008 for Mac
Impact
System compromise: Remote code execution.
Recommended Actions
Apply the patch available from the following web site:
http://www.microsoft.com/technet/security/bulletin/ms08-026.mspx
Telemetry
Coverage
IPS (Regular DB) | |
IPS (Extended DB) |